官术网_书友最值得收藏!

Planning and reconnaissance

In the planning and reconnaissance phase, we define the scope of the penetration test. This initial phase requires a lot of planning, and you need to answer questions, such as:

  • What is the scope of the pentest?
  • What are the restricted URLs?
  • What are the various subdomains in scope?
  • Are there multiple applications hosted on the same domain in different folders?
  • Are there any other platforms where this application is hosted (that is, mobile applications, web applications, desktop applications, and so on)

Once you have answered these questions, you will get some clarity on what is to be tested and what's not. Depending on whether it is a black box or a white box test, further enumeration takes places. In either of the cases, we will have to go ahead and discover all the files and folders of the application in scope and identify the endpoints. Later, in the next chapter, we will see how to discover new files and folders using Burp.

主站蜘蛛池模板: 宜兰市| 顺义区| 大同县| 平武县| 宁国市| 青冈县| 中山市| 阳西县| 句容市| 东丰县| 云浮市| 临沧市| 大英县| 土默特右旗| 青岛市| 吕梁市| 法库县| 德保县| 什邡市| 隆子县| 喀喇沁旗| 宁波市| 石棉县| 铁岭县| 梨树县| 乌海市| 竹溪县| 伊川县| 建水县| 平利县| 星座| 武城县| 平和县| 泉州市| 裕民县| 松潘县| 婺源县| 伊春市| 政和县| 乌拉特后旗| 民丰县|